• NarrativeBear@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    18 hours ago

    When you host something on LAN only you are not exposing the service to the wider internet directly.

    This means someone would need access to your LAN or local area network first (such as your WiFi password) before being able to reach said service.

    Now when you expose something directly to the internet, in a way that for example it displays a publicly accessible webpage, it makes it easier for anyone to reach that webpage, and potentially figure out your login and password information through brute force. Or some other type of exploit that allows full bypass of the login credentials.

    Some self-hoster’s choose to keep their “more sensitive” services on the LAN only, and then use a VPN (that’s hosted privately) to access their LAN remotely from anywhere in the world.

    With a VPN hosted on your LAN it provides a good layer of security as someone would first need to have access to your VPN to then potentially try and get access into your services.

    • iamthetot@piefed.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      17 hours ago

      I appreciate you taking the time to write this out, but I knew all of that and didn’t really address the question. I was asking why the commenter above mine was using an auth service, like Keycloak, on LAN.

      It has been answered a few times, thanks.

      • NarrativeBear@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        16 hours ago

        No worries, not sure how I misunderstood the question, but hopefully it helps someone else out who’s getting into self-hosting.